[event log] add rule type id in custom kibana.alerting field #95411
Labels
Feature:EventLog
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
We don't currently have the rule type id available in the event log docs, but this would be very useful for slicing / dicing the event log data during diagnosis. It is available embedded in the
message
field, so is there in a helpful way for humans looking at individual documents.It would go in here, presumably as
rule_type_id
or such ...kibana/x-pack/plugins/event_log/scripts/mappings.js
Lines 16 to 34 in e894ee9
The text was updated successfully, but these errors were encountered: